Impact
The vulnerability allows contributors to delete arbitrary files within the WordPress site filesystem, which can lead to loss of content, configuration files, or other critical assets and compromise confidentiality, integrity, and availability. The weakness is a classic path traversal and file deletion flaw mapped to CWE-22.
Affected Systems
The flaw affects WordPress H5P plugin versions 1.17.7 and earlier distributed by icc0rz. Any WordPress site that has these plugin versions installed is vulnerable and should be upgraded.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity, but the EPSS is not available, so the exploitation probability is unknown. The vulnerability is not listed in the CISA KEV catalog, suggesting no public exploits yet. A likely attack vector involves an authenticated contributor with plugin privileges uploading or interacting with content that triggers the deletion logic, thereby deleting arbitrary files.
OpenCVE Enrichment